Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
mrx-arafat/CVE-2026-63030-POC
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
PoC for CVE-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept
CVE-2023-44487HIGHbajo ataque18 jul 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir
GitHub PoC
Non-intrusive detection scanner for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 + CVE-2026-60137). Detection-only, no exploitation.
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Het-Kalariya/CVE-2026-20253
CVE-2026-20253CRITICALbajo ataque18 jul 2026
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RIESGO
abrir
GitHub PoC
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2026-56291CRITICALbajo ataque18 jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
100RIESGO
abrir
GitHub PoC1
Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes, cracks credentials, deploys webshell. Supports single target and bulk site lists. For authorized security testing only.
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC6
A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
CybersecSpirit/CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Hunt-Benito/zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri
CVE-2026-10672HIGH18 jul 2026
Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)
41RIESGO
abrir
GitHub PoC5
Use CVE-2026-43074 to disable SELinux on Android (Linux 6.6/6.12)
CVE-2026-43074HIGH18 jul 2026
eventpoll: defer struct eventpoll free to RCU grace period
41RIESGO
abrir
GitHub PoC
CVE-2026-43499 reproduce in Xiaomi 17T. (kernelsu incomplete)
CVE-2026-43499HIGH18 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC7
CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)
CVE-2026-43499HIGH18 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC37
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加设备。
CVE-2026-43499HIGH18 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC15
Use CVE-2026-43499 to disable SELinux on Android
CVE-2026-43499HIGH18 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC12
WordPress 未授权RCE EXP | CVE-2026-63030
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC4
Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC5
Pre-auth RCE in WordPress Core via REST API batch route confusion + WP_Query SQLi (CVE-2026-63030 / CVE-2026-60137). Detection PoC.
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC5
A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.
CVE-2021-44228CRITICALbajo ataqueransomware18 jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
A critical unauthenticated "remote code execution" vulnerability affecting WordPress Core
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC56
Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
akash-osmsec/CVE-2026-44262-
CVE-2026-44262CRITICAL18 jul 2026
Scramble: Remote code execution via evaluation of user-controlled input in validation rules
63RIESGO
abrir
GitHub PoC4
PoC Exploit of WordPress Core Unauthenticated RCE known as WP2Shell
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC102
CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.
CVE-2026-60137MEDIUMbajo ataque18 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir
GitHub PoC8
CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC14
Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion
CVE-2026-63030CRITICALbajo ataque18 jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC1
PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.
CVE-2026-46420MEDIUM18 jul 2026
setup-php: Command Injection in Repository-Derived PHP Version Resolution
33RIESGO
abrir
GitHub PoC1
Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. Developed by Ebrahim Shafiei (EbraSha) for vulnerability assessment, security research, and authorized penetration testing.
CVE-2026-60137MEDIUMbajo ataque18 jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.